且构网

分享程序员开发的那些事...
且构网 - 分享程序员编程开发的那些事

kubernetes api:禁止失败的403个pod:用户"system:serviceaccount:default:journalbeat";无法列出资源"pod"在API组“"中

更新时间:2023-02-20 09:59:48

您的ServiceAccount位于默认名称空间中,因此请按照以下说明修改 ClusterRoleBinding

Your ServiceAccount is in default namespace, so modify the ClusterRoleBinding like following,

---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
  name: journalbeat
roleRef:
  apiGroup: rbac.authorization.k8s.io
  kind: ClusterRole
  name: journalbeat
subjects:
  - kind: ServiceAccount
    name: journalbeat
    namespace: default # as your ServiceAccount is in default namespace